Review SSL/TLS protocols in ELB policies

Ensure outdated SSL/TLS protocols are disabled in Classic ELB security policies.

Description

Enabling SSLv2, SSLv3, TLS 1.0, or TLS 1.1 in a Classic ELB SSL negotiation policy allows connections using outdated protocols. Check whether each protocol is enabled, as well as its attribute name.

Potential impact

Known weaknesses in older SSL/TLS protocols or their cipher suites can weaken transport security between clients and the load balancer.

Remediation

Disable outdated protocols and choose a policy that uses TLS 1.2. For a custom policy, also configure the allowed cipher suites and associate the policy with the HTTPS listener.

Examples

The examples show only the protocol attribute of a custom policy. The revised example enables TLS 1.2; configure cipher suites and the listener association separately.

Before

hcl
resource "aws_load_balancer_policy" "example" {
  load_balancer_name = aws_elb.wu_tang.name
  policy_name        = "wu-tang-ssl"
  policy_type_name   = "SSLNegotiationPolicyType"

  policy_attribute {
    name  = "Protocol-TLSv1"
    value = "true"
  }
}

After

hcl
resource "aws_load_balancer_policy" "example" {
  load_balancer_name = aws_elb.wu_tang.name
  policy_name        = "wu-tang-ssl"
  policy_type_name   = "SSLNegotiationPolicyType"

  policy_attribute {
    name  = "Protocol-TLSv1.2"
    value = "true"
  }
}

References